Zero Day Room
Live
Threats

Outsider Phishing Kit Persists With 700 New Pages

The Outsider phishing-as-a-service kit operated by ChenLun has generated over 700 new pages since a June law enforcement takedown, having previously

The Outsider phishing-as-a-service kit operated by ChenLun has generated over 700 new pages since a June law enforcement...

A phishing-as-a-service operation has continued its campaigns despite a major coordinated takedown effort. According to Group-IB, more than 700 new phishing pages linked to the Outsider Phishing Kit were identified in the month following the disruption.

Group-IB's research, published on September 3, details the activities of the kit, operated by a threat actor known as ChenLun. The firm tracked over 100,000 phishing pages targeting 54 or more countries between December 2025 and May 2026. This activity persisted after Google filed a civil lawsuit against the group on June 12 and the FBI's Cyber Division announced Operation Ghost Hook with Google and Lumen's Black Lotus Labs the following day. The FBI stated the operation seized the group's core admin servers, a Shopify storefront, about $100,000 from payment wallets, and thousands of domains.

New Pages Appear After Takedown

Before Operation Ghost Hook, Group-IB had linked over 10,000 unique domains to the Outsider kit. The subsequent identification of more than 700 additional domains indicates that affiliates kept using the service even after infrastructure seizures. The platform contained 267 ready-made phishing templates impersonating a wide range of organizations.

The kit's campaigns were delivered via SMS and managed through a Telegram ecosystem for sales and affiliate coordination. ChenLun has since deleted that Telegram channel. Prior to its suspension, Group-IB said the main group had over 5000 subscribers and more than 230 users who had purchased the kit.

Researchers examined one smishing campaign that impersonated Singapore's Land Transport Authority. The messages created urgency around a fake data synchronization issue and included instructions on how to bypass a phone's spam filters. The cloned portal collected vehicle registration and phone numbers before redirecting victims to fake payment screens. Group-IB said the harvested numbers were intended for later interception of SMS authentication codes.

Live Interaction Supports Credential Theft

The Outsider Phishing Kit incorporated adversary-in-the-middle capabilities to interact with victims during the attack. Group-IB explained that operators could dynamically serve various multi-factor authentication challenges-like SMS, email, PIN, or app-based prompts-and redirect victims to earlier pages to ask for more payment details.

The kit used WebSockets to enable live communication between phishing pages and an operator panel. Data entered by victims was transmitted in real time, even if a user abandoned a form before submitting it. JavaScript components were identified that captured financial details, bank credentials, PayPal information, and authentication codes. The researchers also found mechanisms for tracking victims across browser sessions and detecting security crawlers.

Mitigation and Detection Recommendations

The phishing pages followed a consistent file-naming convention, using an alphabetical prefix to mark a victim's stage in the attack flow. Group-IB recommends that organizations track new pages through these file-name signatures to trigger faster takedowns.

To protect against this threat, the company advised continuous monitoring for SMS-linked brand abuse. It also recommended that individuals verify any alerts through official apps rather than clicking links in messages.

Related coverage

More from Threats